Splunk® Enterprise

Installation Manual

Download manual as PDF

Download topic as PDF

Install the universal forwarder on AIX

Important: Splunk does not offer an installation package for Splunk Enterprise on AIX. It does, however, offer a universal forwarder installation package for AIX versions 6.1 and 7.1. These instructions detail how to install the universal forwarder on those versions of AIX.

To use Splunk Enterprise on AIX, you must download an older version of the Splunk software.


The user that you install the universal forwarder as must have permission to read /dev/random and /dev/urandom or the installation will fail.

Basic install

The AIX universal forwarder installer comes in tar file form. There is no current version of Splunk Enterprise available for AIX.

When you install with the tar file:

  • Splunk Enterprise does not create the splunk user automatically. If you want Splunk Enterprise to run as a specific user, you must create the user manually.
  • Be sure the disk partition has enough space to hold the uncompressed volume of the data you plan to keep indexed.
  • We recommend you use GNU tar to unpack the tar files, as AIX tar can fail to unpack long file names, fail to overwrite files, and other problems. If you must use the system tar, be sure to check the output for error messages. GNUtar is typically installed as part of the AIX Toolbox for Linux Applications package /opt/freeware/bin/tar

To install the universal forwarder on an AIX system, expand the tar file into an appropriate directory. The default install directory is /opt/splunkforwarder.

What's next?

Now that you have installed the Splunk universal forwarder, visit the Universal Forwarder manual to:

Install the universal forwarder on FreeBSD
Install the universal forwarder on HP-UX

This documentation applies to the following versions of Splunk® Enterprise: 6.4.0, 6.4.1, 6.4.2, 6.4.3, 6.4.4, 6.4.5, 6.5.0, 6.5.1

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters